orphaned users
Posted in 2017
The poster asked whether cloning a Linux server running Informix 11.5 leaves database users "orphaned" as can happen in SQL Server, where restored database users lose their link to engine logins (identified by SID) and must be re-tied with ALTER USER. Answers: Informix doesn't work that way — it authenticates against the operating system, so as long as the same OS users exist on the cloned machine, access works. One caveat noted: remote/"trusted" connections depend on how the cloned host sees the client machines. Poster was satisfied.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Platform-Specific Issues
Hi, if you clone a Linux server that has an Informix 11.5 instance, do the database users become orphaned like they do in sql server? I haven't read anything that shows that they do. Thanks Benji
People here may not know nothing about SQL Server. Can you elaborate on what "orphaned" means? Most Informix installations use OS authentication. Although it's possible to authenticate on external sources, that's not the most common scenario. Regards. On Fri, Jan 6, 2017 at 1:27 PM, BENJI LONG <ruggedmouse@hotmail.com> wrote: > Hi, if you clone a Linux server that has an Informix 11.5 instance, do the > database users become orphaned like they do in sql server? I haven't read > anything that shows that they do. > > Thanks > Benji > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a1147ccc819f44705456df631
Hi, I now think this will work ok as the server admins are cloning and not restoring. In sql server, from a high level, when you create a user login, there is a security ID associated with that particular instance, so when you restore to another instance, the user becomes "orphaned". Then you have to run a command to tie that user into the new instance with a new security ID. I'm now thinking (hoping) that since they are cloning the complete server, that it will work. I'm not familiar with Linux(this is a new assignment) so I'll read up on users with Informix, and the Linux OS Thanks Benji
If the users are authenticated on the OS with user/password it will work. If the connections are remote and "trusted" it will depend on how the "cloned" machine will see the client machine. Regards. On Fri, Jan 6, 2017 at 3:00 PM, BENJI LONG <ruggedmouse@hotmail.com> wrote: > Hi, I now think this will work ok as the server admins are cloning and not > restoring. > > In sql server, from a high level, when you create a user login, there is a > security ID associated with that particular instance, so when you restore > to > another instance, the user becomes "orphaned". Then you have to run a > command > to tie that user into the new instance with a new security ID. > > I'm now thinking (hoping) that since they are cloning the complete server, > that it will work. > > I'm not familiar with Linux(this is a new assignment) so I'll read up on > users > with Informix, and the Linux OS > > Thanks > Benji > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a114abc800a577d05456e5dcd
In Squeal you have logins that are tied to the database engine and users that are tied to databases. A user without a login is orphaned. This query finds them: USE mydatabase select dp.name [user_name] ,dp.type_desc [user_type] ,isnull(sp.name,'Orhphaned!') [login_name] ,sp.type_desc [login_type] from sys.database_principals dp left join sys.server_principals sp on (dp.sid = sp.sid) where dp.type in ('S','U','G') and dp.principal_id >4 order by sp.name This fixes them: ALTER USER [username] WITH LOGIN=[username] --EEM > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Fernando Nunes > Sent: Friday, January 06, 2017 08:38 AM > To: ids@iiug.org > Subject: Re: orphaned users [38471] > > People here may not know nothing about SQL Server. > Can you elaborate on what "orphaned" means? > > Most Informix installations use OS authentication. Although it's > possible to authenticate on external sources, that's not the most > common scenario. > Regards. > > On Fri, Jan 6, 2017 at 1:27 PM, BENJI LONG <ruggedmouse@hotmail.com> > wrote: > > > Hi, if you clone a Linux server that has an Informix 11.5 instance, > do > > the database users become orphaned like they do in sql server? I > > haven't read anything that shows that they do. > > > > Thanks > > Benji > > > > > > ************************************************************ > > ******************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > -- > Fernando Nunes > Portugal > > http://informix-technology.blogspot.com > My email works... but I don't check it frequently... > > --001a1147ccc819f44705456df631 > > > *********************************************************************** > ******** > Forum Note: Use "Reply" to post a response in the discussion forum.
Informix authenticates users using the OS, so as long as you define the users on the new machine they will be fine. Art Art S. Kagel, President and Principal Consultant ASK Database Management www.askdbmgt.com Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Fri, Jan 6, 2017 at 8:27 AM, BENJI LONG <ruggedmouse@hotmail.com> wrote: > Hi, if you clone a Linux server that has an Informix 11.5 instance, do the > database users become orphaned like they do in sql server? I haven't read > anything that shows that they do. > > Thanks > Benji > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --94eb2c05cf722aebed05456edb63
That is a better explanation than what I gave. Thanks.